Skip to content
Cloudflare Docs

API token permissions

Permissions are segmented into three categories based on resource:

  • Zone permissions
  • Account permissions
  • User permissions

Each category contains permission groups related to those resources. DNS permissions belong to the Zone category, while Billing permissions belong to the Account category. Below is a list of the available token permissions.

To obtain an updated list of token permissions, including the permission ID and the scope of each permission, use the List permission groups endpoint.

User permissions

The applicable scope of user permissions is com.cloudflare.api.user.

NameDescription
API Tokens ReadGrants read access to user's API tokens.
API Tokens EditGrants write access to user's API tokens.
Memberships ReadGrants read access to a user's account memberships.
Memberships EditGrants write access to a user's account memberships.
User Details ReadGrants read access to user details.
User Details EditGrants write access to user details.

Account permissions

The applicable scope of account permissions is com.cloudflare.api.account.

| Name | Description | | ---------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | | Access: Apps and Policies Read | Grants read access to Cloudflare Access applications and policies | resources. | | Access: Apps and Policies Revoke | Grants ability to revoke Cloudflare Access application tokens | | Access: Apps and Policies Edit | Grants write access to Cloudflare Access applications and policies | | Access: Audit Logs Read | Grants read access to Cloudflare Access audit logs. | | Access: Custom Pages Read | Grants read access to Cloudflare Access custom block pages. | | Access: Custom Pages Edit | Grants write access to Cloudflare Access custom block pages. | | Access: Device Posture Read | Grants read access to Cloudflare Access device posture. | | Access: Device Posture Edit | Grants write access to Cloudflare Access device posture. | | Access: Mutual TLS Certificates Read | Grants read access to Cloudflare Access mTLS certificates. | | Access: Mutual TLS Certificates Edit | Grants write access to Cloudflare Access mTLS certificates. | | Access: Organizations, Identity Providers, and Groups Read | Grants read access to Cloudflare Access account resources. | | Access: Organizations, Identity Providers, and Groups Revoke | Grants ability to revoke user sessions to Cloudflare Access account resources. | | Access: Organizations, Identity Providers, and Groups Edit | Grants write access to Cloudflare Access account resources. | | Access: Service Tokens Read | Grants read access to Cloudflare Access service tokens. | | Access: Service Tokens Edit | Grants write access to Cloudflare Access service tokens. | | Access: SSH Auditing Read | Grants read access to Cloudflare Access SSH CAs. | | Access: SSH Auditing Edit | Grants write access to Cloudflare Access SSH CAs. | | Account Analytics Read | Grants read access to account analytics. | | Account Custom Pages Read | Grants read access to account-level Error Pages. | | Account Custom Pages Edit | Grants write access to account-level Error Pages. | | Account Filter Lists Read | Grants read access to Account Filter Lists. | | Account Filter Lists Edit | Grants write access to Account Filter Lists. | | Account Firewall Access Rules Read | Grants read access to account firewall access rules. | | Account Firewall Access Rules Edit | Grants write access to account firewall access rules. | | Account Rulesets Read | Grants read access to Account Rulesets. | | Account Rulesets Edit | Grants write access to Account Rulesets. | | Account Settings Read | Grants read access to Account resources, account membership, and account level features. | | Account Settings Edit | Grants write access to Account resources, account membership, and account level features. | | Account: SSL and Certificates Read | Grants read access to SSL and Certificates. | | Account: SSL and Certificates Edit | Grants write access to SSL and Certificates. | | Account WAF Read | Grants read access to Account WAF. | | Account WAF Edit | Grants write access to Account WAF. | | Address Maps Edit | Grants write access to Address Maps | | Address Maps Read | Grants read access to Address Maps | | Allow Request Tracer Read | Grants read access to Request Tracer. | | API Gateway Read | Grants read access to API Gateway (including API Shield) for all domains in an account. | | API Gateway Edit | Grants write access to API Gateway (including API Shield) for all domains in an account. | | Billing Read | Grants read access to billing profile, subscriptions, and access to fetch invoices and entitlements. | | Billing Edit | Grants write access to billing profile, subscriptions, and access to fetch invoices and entitlements. | | Bulk URL Redirects Read | Grants read access to Bulk Redirects. | | Bulk URL Redirects Edit | Grants write access to Bulk Redirects. | | China Network Steering Read | Grants read access to China Network Steering. | | China Network Steering Edit | Grants write access to China Network Steering. | | Cloudchamber Read | Grants read access to Cloudchamber deployments. | | Cloudchamber Edit | Grants write access to Cloudchamber deployments. | | Cloudflare Realtime Read | Grants read access to Cloudflare Realtime. | | Cloudflare Realtime Edit | Grants write access to Cloudflare Realtime. | | Cloudflare DEX Read | Grants read access to Digital Experience Monitoring. | | Cloudflare DEX Edit | Grants write access to Digital Experience Monitoring. | | Cloudflare Images Read | Grants read access to Cloudflare Images. | | Cloudflare Images Edit | Grants write access to Cloudflare Images. | | Cloudflare One Connector: cloudflared Read | Grants read access to cloudflared connectors | | Cloudflare One Connector: cloudflared Edit | Grants write access to cloudflared connectors | | Cloudflare One Connector: WARP Read | Grants read access to WARP Connectors | | Cloudflare One Connector: WARP Edit | Grants write access to WARP Connectors | | Cloudflare One Connectors Read | Grants read access to Cloudflare One connectors | | Cloudflare One Connectors Edit | Grants write access to Cloudflare One connectors | | Cloudflare One Networks Read | Grants read access to Cloudflare One routes and virtual networks | | Cloudflare One Networks Edit | Grants write access to Cloudflare One routes and virtual networks | | Cloudflare Pages Read | Grants access to view Cloudflare Pages projects. | | Cloudflare Pages Edit | Grants access to create, edit and delete Cloudflare Pages projects. | | Cloudflare Tunnel Read | Grants access to view Cloudflare Tunnels. | | Cloudflare Tunnel Edit | Grants access to create and delete Cloudflare Tunnels. | | Cloudforce One Read | Grants read access to Cloudforce One. | | Cloudforce One Edit | Grants write access to Cloudforce One. | | Email Security Read | Grants read access to Cloud Email Security. | | Email Security Edit | Grants write access to Email Security. | | Constellation Read | Grants read access to Constellation. | | Constellation Edit | Grants write access to Constellation. | | Containers Read | Grants read access to Containers. | | Containers Edit | Grants write access to Containers. | | D1 Read | Grants read access to D1. | | D1 Edit | Grants write access to D1. | | DDoS Botnet Feed Read | Grants read access to Botnet Feed reports. | | DDoS Botnet Feed Edit | Grants write access to Botnet Feed configuration. | | DDoS Protection Read | Grants read access to DDoS protection. | | DDoS Protection Edit | Grants write access to DDoS protection. | | DNS Firewall Read | Grants read access to DNS Firewall. | | DNS Firewall Edit | Grants write access to DNS Firewall. | | Email Routing Addresses Read | Grants read access to Email Routing Addresses. | | Email Routing Addresses Edit | Grants write access to Email Routing Addresses. | | Hyperdrive Read | Grants read access to Hyperdrive. | | Hyperdrive Edit | Grants write access to Hyperdrive. | | Intel Read | Grants read access to Intel. | | Intel Edit | Grants write access to Intel. | | Integration Edit | Grants write access to integrations. | | IOT Read | Grants read access to IOT. | | IOT Edit | Grants write access to IOT. | | IP Prefixes: Read | Grants access to read IP prefix settings. | | IP Prefixes: Edit | Grants access to read/write IP prefix settings. | | IP Prefixes: BGP On Demand Read | Grants access to read IP prefix BGP configuration. | | IP Prefixes: BGP On Demand Edit | Grants access to read and change IP prefix BGP configuration. | | L3/4 DDoS Managed Ruleset Read | Grants read access to L3/4 DDoS managed ruleset. | | L3/4 DDoS Managed Ruleset Edit | Grants write access to L3/4 DDoS managed ruleset. | | Load Balancing: Monitors and Pools Read | Grants read access to account level load balancer resources. | | Load Balancing: Monitors and Pools Edit | Grants write access to account level load balancer resources. | | Logs Read | Grants read access to logs using Logpull or Instant Logs. | | Logs Edit | Grants read and write access to Logpull, Logpush, and Instant Logs. | | Magic Firewall Read | Grants read access to Magic Firewall. | | Magic Firewall Edit | Grants write access to Magic Firewall. | | Magic Firewall Packet Captures Read | Grants read access to Packet Captures. | | Magic Firewall Packet Captures Edit | Grants write access to Packet Captures. | | Magic Network Monitoring Read | Grants read access to Magic Network Monitoring. | | Magic Network Monitoring Edit | Grants write access to Magic Network Monitoring. | | Magic Transit Read | Grants read access to manage a user's Magic Transit prefixes. | | Magic Transit Edit | Grants write access to manage a user's Magic Transit prefixes. | | Notifications Read | Grants read access to Notifications. | | Notifications Edit | Grants write access to Notifications. | | Page Shield Read | Grants read access to Page Shield. | | Page Shield Edit | Grants write access to Page Shield. | | Workers Pipelines Read | Grants read access to Cloudflare Pipelines. | | Workers Pipelines Edit | Grants write access to Cloudflare Pipelines. | | Pub/Sub Read | Grants read access to Pub/Sub. | | Pub/Sub Edit | Grants write access to Pub/Sub. | | Queues Read | Grants read access to Queues. | | Queues Edit | Grants write access to Queues. | | Rule Policies Read | Grants read access to Rule Policies. | | Rule Policies Edit | Grants write access to Rule Policies. | | Stream Read | Grants read access to Cloudflare Stream. | | Stream Edit | Grants write access to Cloudflare Stream. | | Transform Rules Read | Grants read access to Transform Rules. | | Transform Rules Edit | Grants write access to Transform Rules. | | Turnstile Read | Grants read access to Turnstile. | | Turnstile Edit | Grants write access to Turnstile. | | URL Scanner Read | Grants read access to URL Scanner. | | URL Scanner Edit | Grants write access to URL Scanner. | | Vectorize Read | Grants read access to Vectorize. | | Vectorize Edit | Grants write access to Vectorize. | | Workers AI Read | Grants read access to Workers AI. | | Workers AI Edit | Grants write access to Workers AI. | | Workers CI Read | Grants read access to Workers CI. | | Workers CI Edit | Grants write access to Workers CI. | | Workers KV Storage Read | Grants read access to Cloudflare Workers KV Storage. | | Workers KV Storage Edit | Grants write access to Cloudflare Workers KV Storage. | | Workers R2 Storage Read | Grants read access to Cloudflare R2 Storage. | | Workers R2 Storage Edit | Grants write access to Cloudflare R2 Storage. | | Workers Scripts Read | Grants read access to Cloudflare Workers scripts. | | Workers Scripts Edit | Grants write access to Cloudflare Workers scripts. | | Workers Tail Read | Grants wrangler tail read permissions. | | Zero Trust Read | Grants read access to Cloudflare Zero Trust resources. | | Zero Trust Report | Grants reporting access to Cloudflare Zero Trust. | | Zero Trust Edit | Grants write access to Cloudflare Zero Trust resources. | | Zero Trust: PII Read | Grants read access to Cloudflare Zero Trust PII. | | Zero Trust: Seats Edit | Grants write access to the number of Zero Trust seats your organization can use (and be billed for). |

Zone permissions

The applicable scope of zone permissions is com.cloudflare.api.account.zone.

NameDescription
Access: Apps and Policies ReadGrants read access to Cloudflare Access zone resources.
Access: Apps and Policies RevokeGrants ability to revoke all tokens to Cloudflare Access zone resources.
Access: Apps and Policies EditGrants write access to Cloudflare Access zone resources.
Analytics ReadGrants read access to analytics.
API Gateway ReadGrants read access to API Gateway zone resources.
API Gateway EditGrants write access to API Gateway zone resources.
Apps EditGrants full access to Cloudflare Apps (deprecated, refer to Workers instead).
Bot Management ReadGrants read access to Bot Management.
Bot Management EditGrants write access to Bot Management.
Bot Management Feedback ReadGrants read access to Bot Management feedback.
Bot Management Feedback EditGrants write access to Bot Management feedback.
Cache PurgeGrants access to purge cache.
Cache Rules ReadGrants read access to Cache Rules.
Cache Rules EditGrants write access to Cache Rules.
Cloud Connector ReadGrants read access to Cloud Connector rules.
Cloud Connector EditGrants write access to Cloud Connector rules.
Config Rules ReadGrants read access to Configuration Rules.
Config Rules EditGrants write access to Configuration Rules.
Custom Error Rules ReadGrants read access to Custom Error Rules.
Custom Error Rules EditGrants write access to Custom Error Rules.
Custom Pages ReadGrants read access to Custom Error Pages.
Custom Pages EditGrants write access to Custom Error Pages.
Dmarc Management ReadGrants read access to DMARC Management.
Dmarc Management EditGrants write access to DMARC Management.
DNS ReadGrants read access to DNS.
DNS WriteGrants write access to DNS.
Email Routing Rules ReadGrants read access to Email Routing Rules.
Email Routing Rules EditGrants write access to Email Routing Rules.
Firewall Services ReadGrants read access to Firewall resources.
Firewall Services EditGrants write access to Firewall resources.
Health Checks ReadGrants read access to Health Checks.
Health Checks EditGrants write access to Health Checks.
HTTP DDoS Managed Ruleset ReadGrants read access to HTTP DDoS managed ruleset.
HTTP DDoS Managed Ruleset EditGrants write access to HTTP DDoS managed ruleset.
Load Balancers ReadGrants read access to load balancer resources.
Load Balancers EditGrants write access to load balancer resources.
Logs ReadGrants read access to logs using Logpull.
Logs EditGrants write access to Logpull and Logpush.
Managed Headers ReadGrants read access to Managed Headers.
Managed Headers EditGrants write access to Managed Headers.
Origin Rules ReadGrants read access to Origin Rules.
Origin Rules EditGrants write access to Origin Rules.
Page Rules ReadGrants read access to Page Rules.
Page Rules EditGrants write access to Page Rules.
Page Shield ReadGrants read access to Page Shield.
Page Shield EditGrants write access to Page Shield.
Response Compression ReadGrants read access to Response Compression.
Response Compression EditGrants write access to Response Compression.
Sanitize ReadGrants read access to sanitization.
Sanitize EditGrants write access to sanitization.
Single Redirect ReadGrants read access to zone-level Single Redirects.
Single Redirect EditGrants write access to zone-level Single Redirects.
SSL and Certificates ReadGrants read access to SSL configuration and certificate management.
SSL and Certificates EditGrants write access to SSL configuration and certificate management.
Transform Rules ReadGrants read access to Transform Rules.
Transform Rules EditGrants write access to Transform Rules.
Waiting Room ReadGrants read access to Waiting Room.
Waiting Room EditGrants write access to Waiting Room.
Web3 Hostnames ReadGrants read access to Web3 Hostnames.
Web3 Hostnames EditGrants write access to Web3 Hostnames.
Workers Routes ReadGrants read access to Cloudflare Workers and Workers KV Storage.
Workers Routes EditGrants write access to Cloudflare Workers and Workers KV Storage.
Zaraz ReadGrants read access to Zaraz zone level settings.
Zaraz EditGrants write access to Zaraz zone level settings.
Zone ReadGrants read access to zone management.
Zone EditGrants write access to zone management.
Zone Settings ReadGrants read access to zone settings.
Zone Settings EditGrants write access to zone settings.
Zone Versioning ReadGrants read access to Zone Versioning at zone level.
Zone Versioning EditGrants write access to Zone Versioning at zone level.
Zone WAF ReadGrants read access to Zone WAF.
Zone WAF EditGrants write access to Zone WAF.